AICPA Cybersecurity Risk Management Examination Report

Now what? In the midst of GDPR, new PCI DSS 3.2 standards, and expanded controls for all privacy aspects of your SOC 2, things just got ratcheted up another notch.  The AICPA has released its Descriptions Criteria for the examination of the Entity's Cybersecurity Risk Management Program.  Needless to say, the evidence requirements are piling up.  EnterpriseGRC Solutions has already loaded this standard to our existing SOC2 and other assessment and mapping programs.  To help you assess where this new guidance will be sending your external auditors, we've included a summary of the text below.

Please visit the AICPA to purchase documentation and training on Cybersecurity Risk Management and other new requirements.

"Search Cybersecurity+Risk+Management+Examination | AICPA"

As stated within the AICPA FACT SHEET:Trust

The framework for reporting on an entity’s cybersecurity risk management program calls for management to prepare certain information about the entity’s cybersecurity risk management program and for the CPA to examine and report on that information in accordance with the AICPA’s attestation standards. The resulting cybersecurity report includes the following three key sets of information:

  1. Management’s description

The first component is a management-prepared narrative description of the entity’s cybersecurity risk management program (the description). This description is designed to provide information about how the entity identifies its most sensitive information, the ways in which the entity manages the cybersecurity risks that threaten it, and the key security policies and processes implemented and operated to protect the entity’s information assets against those risks. The description provides the context report users need to understand the conclusions, expressed by management in its assertion and by the CPA in the opinion, about the effectiveness of the controls included in the entity’s cybersecurity risk management program.

  1. Management’s assertion

Management provides an assertion about whether the description is presented in accordance with the description criteria and whether the controls within the program were effective to achieve the entity’s cybersecurity objectives based on the control criteria. (These criteria are discussed below.)

  1. The practitioner’s opinion

The final component in the reporting framework is the CPA’s opinion on the description and on the effectiveness of controls within that program.  

If you need assistance to design or map your existing audit program to these new criteria, please give us a call.  We're ready for you.

AICPA Cybersecurity Risk Management

We've extracted and formatted some of the content to help you get started.  Here's the high-level content of the guidance report.

Main Menu